CVE-2026-24420 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attach…
Medium CVSS: 6.5

CVE-2026-24420

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a incomprehensive permissions check. The presence of a right key is improperly validated as proof of authorization in attachment.php. Additionally, the group and user permission logic contains a flawed conditional expression that may allow unauthorized access. This issue has been fixed in version
Vendor
Phpmyfaq
Product
Phpmyfaq
CWE
CWE-284
Yayın Tarihi
2026-01-24 03:16:00
Güncelleme
2026-01-28 18:25:46
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar